Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

Gamaredon fileless WinRAR intrusion chain in Ukrainian state and infrastructure networks

Updated 01.06.2026 14:00
Case score 56
Case score 56 Members 1 Latest activity 01.06.2026 14:00
Patch available
Members 1 First seen 01.06.2026 14:00 Last seen 01.06.2026 14:00 Updated 01.06.2026 14:00

Overview

**Gamaredon** remained active in January 2026 against **Ukrainian government, military, and critical-infrastructure** networks, using a booby-trapped xHTML file and malicious RAR archive to exploit **CVE-2025-8088** in **WinRAR**. The intrusion chain places a hidden HTA file in Startup, leans on **fileless VBScript**, stores components in **NTFS Alternate Data Streams**, and uses dead-drop resolvers on **Telegram** and **Cloudflare** to support long-term access and document theft. Defensive focus has shifted to patching **WinRAR** to **7.13 or later** and hunting for startup-folder HTA files, alternate data streams, suspicious VBScript, scheduled tasks, registry changes, and removable-media spread. The activity is ongoing, but available evidence does not quantify how many organizations were compromised or how much data was taken.

Signals

8 derived
CVEs/products
CVE
Victims/regions
Sector government Sector military Victim region Ukraine
Remediation
Remediation Patch available
Status
Campaign status Active
Threat context
Actor Gamaredon Malware

Malware context

1 families · 1 tools
Tools
Dead Drop Resolvers (DDR)

Member happenings

1 related
Campaign Gamaredon Ukraine espionage campaign targeting government, military and critical infrastructure
Updated 01.06.2026 14:00 Lead Contribution 56
Objective Espionage Campaign Active Patch Patch Available

The **Gamaredon** espionage campaign remained active in **January 2026**, targeting **Ukrainian government, military, and critical-infrastructure** networks to steal documents and preserve access. The operation shifted toward **fileless VBScript** and **NTFS Alternate Data Streams**, reducing on-disk traces and making detection harder. It also used **USB sticks**, **network drives**, and dead-drop command-and-control to spread quietly across compromised environments.